On Sun, 6 Dec 2009, sird@rckc.at wrote:
>
> ian, isnt allow-same-origin confusing? since if its same origin what
> stops you from linking it and bypassing those protections.
allow-same-origin is only really intended to be used with the
aforementioned doc="" attribute idea (eventually) and data: URIs (in the
meantime). The example you mention is indeed misleading.
--
Ian Hickson U+1047E )\._.,--....,'``. fL
http://ln.hixie.ch/ U+263A /, _.. \ _\ ;`._ ,.
Things that are impossible just take longer. `._.-(,_..'--(,_..'`-.;.'